Privacy-Preserving and Secure Decentralized Identity Management for Multiple Controllers
Huijiong Yang, Bin Xie, Jianhuan Wang, Guyue Li, Bin Xiao · 2024
Decentralized identity (DID) is pivotal to Web3 applications as it empowers users to manage their identities and credentials without relying on any central authority. Multi-controller is a new and indispensable scenario outlined by the W3C DID standards, while its privacy and security issues have not yet been fully explored. In this paper, we find two new attacks caused by multiple controllers toward DID management, and propose a privacy-preserving and secure identity management scheme to defend against both attacks. The first proposed controller-correlation attack allows an attacker to infer relationships between different subjects by correlating the public keys uploaded by multiple controllers to the blockchain. To avoid this kind of privacy leakage, we propose a masking scheme based on the Merkle tree, which allows the controllers to prove their ownership over the multi-controller identities without publicizing the plaintext of their public keys. The other identity impersonation attack exploits insecure controller revocation caused by high block synchronization latency. To resist this attack, we propose a lightweight authentication scheme. The holders provide digest freshness proof while the verifiers only need to download block headers. To evaluate the feasibility of our proposed scheme, we implement our system on the Sepolia TestNet. The experimental result demonstrates that our system can prevent these attacks with acceptable gas consumption and time consumption, compared with the state-of-the-art.